Skip to content

npm Tracker

Anyone can publish to npm, and a package your build already trusts can turn hostile in a single release. Most of it is the same handful of tricks: run on install, read the environment, post it somewhere. Thanks to Artifactly for the feed, and to Permiso, we appreciate you.

Updated 03:01 UTC

Packages flagged per day

0 2.5 5 7.5 10 Sep 10, 2026: 9 added 9 09/10 Sep 11, 2026: 0 added 0 09/11 Sep 12, 2026: 0 added 0 09/12 Sep 13, 2026: 0 added 0 09/13 Sep 14, 2026: 0 added 0 09/14 Sep 15, 2026: 0 added 0 09/15 Sep 16, 2026: 0 added 0 09/16

Latest 9 investigated

npm releases flagged as malicious, the verdict on each, and the date it was published
Package Version Verdict Published
file-type-detector investigation, opens in a new tab 1.1.1 Confirmed Sep 10, 2026
22:33 UTC
open-item-validator investigation, opens in a new tab 1.0.5 Confirmed Sep 10, 2026
22:18 UTC
open-item-validator investigation, opens in a new tab 1.0.3 Confirmed Sep 10, 2026
22:17 UTC
gloggo investigation, opens in a new tab 1.1.2 Confirmed Sep 10, 2026
22:15 UTC
gloggo investigation, opens in a new tab 1.1.4 Confirmed Sep 10, 2026
22:02 UTC
file-type-detector investigation, opens in a new tab 1.1.0 Confirmed Sep 10, 2026
21:47 UTC
toru-ultimate investigation, opens in a new tab 1.0.0 Confirmed Sep 10, 2026
21:43 UTC
bx-ui-view investigation, opens in a new tab 1.0.0 Confirmed Sep 10, 2026
21:28 UTC
@yongot/canary-mcp-isolation investigation, opens in a new tab 1.0.1 Confirmed Sep 10, 2026
21:27 UTC

Supply Chain Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.